hacker-news · Crawled Jul 13, 2026
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
2 IoCs 4 CVEs
Read original article ↗
AI Summary
The U.S. CISA has added two critical vulnerabilities in Joomla extensions iCagenda and Balbooa Forms to its Known Exploited Vulnerabilities catalog due to active zero-day exploitation. CVE-2026-48939 and CVE-2026-56291, both rated 10.0 CVSS, allow unauthenticated remote code execution via arbitrary file upload. These flaws are being exploited in automated attacks to deploy web shells on vulnerable Joomla sites. Australia's ACSC has also warned of a global campaign exploiting similar CMS vulnerabilities.
AI-extracted · verify before operational use
Extracted Entities 4 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 15 techniques
T1021 Remote Services · Lateral Movement T1046 Network Service Discovery · Discovery T1059 Command and Scripting Interpreter · Execution T1059.001 PowerShell · Execution T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1190 Exploit Public-Facing Application · Initial Access T1505.003 Web Shell · Persistence T1566 Phishing · Initial Access T1027 Obfuscated Files or Information · Defense Evasion